Improperly implemented security check for standard in Google Chrome - CVE-2020-6477

 

Improperly implemented security check for standard in Google Chrome - CVE-2020-6477

Published: May 19, 2020 / Updated: May 19, 2020


Vulnerability identifier: #VU28085
CSH Severity: High
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-6477
CWE-ID: CWE-358
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to incorrect implementation in installer in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


Affected software

Google Chrome
Arch Linux
Gentoo Linux
Fedora
SUSE Linux
Opensuse
chromium

How to mitigate CVE-2020-6477

Update to version 83.0.4103.61.

Google Chrome - update to 83.0.4103.61
chromium - addressed in versions 83.0.4103.106-1.el7, 83.0.4103.106-1.el8, 83.0.4103.106-1.fc31, 83.0.4103.106-1.fc32, 83.0.4103.116-3.el7, 83.0.4103.116-3.el8, 83.0.4103.116-3.fc31, 83.0.4103.116-3.fc32

External References

Related Security Bulletins